< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Linux security vulnerabilities affect major distributions and kernel

A series of security vulnerabilities and exploits have been identified across major Linux distributions, affecting software including nginx, Mozilla, and .NET. Red Hat Enterprise Linux (RHEL) has issued 48 advisories, with 40 rated as important, necessitating priority updates and reboots for components such as the kernel, gstreamer, and corosync.

In Fedora, a patched open62541 library contains 17 CVEs, including a flaw allowing arbitrary code execution. Debian has also released updates to address issues with nginx, including a fix for a previous regression in a build dependency.

Additionally, working exploit code has been released for four Linux kernel flaws: DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. Discovered by researcher Asim Manizada, these vulnerabilities could allow a local user to gain root access. While kernel maintainers have released fixes for these flaws, the publication of the exploit code increases the risk for systems running outdated kernels, particularly those with unprivileged user namespaces enabled.

Entities

Asim Manizada · Debian · Linux · Mozilla · Red Hat Enterprise Linux